Tag: backdoors

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners
News

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners

The Aviatrix Controller cloud networking product has a recently discovered severe security weakness that is being actively exploited in the wild to install cryptocurrency miners and backdoors. The maximum severity vulnerability CVE-2024-50603 (CVSS score: 10.0), which might lead to unauthenticated remote code execution, has been weaponized, according to cloud security company Wiz, which stated it is presently reacting to "multiple incidents" using this vulnerability. In other words, if the vulnerability is successfully exploited, it may allow an attacker to insert malicious operating system commands since some API endpoints fail to sufficiently sanitize user-supplied input read more about Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners. Get...
Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions
News

Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions

Two previously unreported backdoors identified as LunarWeb and LunarMail were directed towards an unidentified European Ministry of Foreign Affairs (MFA) and its three diplomatic missions in the Middle East. Using tactical overlaps with previous campaigns identified as being directed by the group, ESET, which detected the activity, linked it with medium confidence to the Russia-aligned cyberespionage group Turla (also known as Iron Hunter, Pensive Ursa, Secret Blizzard, Snake, Uroburos, and Venomous Bear). Security researcher Filip Jurčacko stated that LunarWeb, which is installed on servers, mimics normal requests and uses HTTP(S) for its C&C [command-and-control] communications, while LunarMail, which is installed on workstations, is persistent as an Outlook add-in and uses em...